Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ian_Harrison
New Contributor

TCP.Split.Handshake - Should I block it?

Hi 

 

I am seeing a lot of IPS alerts from mobile devices on our wifi generating alerts for TCP.Split.Handshake.  By default the rules on our Fortigate (v5.2.3) only detect TCP.Split.Handshake, question is should I change it to block?

 

Thanks for any help

 

Regards

 

Ian

Web: www.activatelearning.ac.uk Twitter: twitter.com/activate_learn Facebook: facebook.com/Activate-Learning
1 REPLY 1
razor
New Contributor III

I would like to advise you to read the following article: http://watchguardsecurity...and-does-it-affect-me/

 

A piece of the story:

"First, you should know that this attack cannot punch holes in your firewall, willy-nilly, without user interaction. A key mitigating factor to the attack is that a client within your network must first make a connection to a malicious server on the internet, before this attack can even start. Some of the descriptions of the attack, which claim an external attacker can trick a firewall into giving them access as a trusted IP, seem to leave this fact out. So if you were worried that external attackers can just hop through your firewall on their own, don’t be."

Fortinet Network Security Professional (NSE4)

Fortinet Network Security Professional (NSE4)
Labels
Top Kudoed Authors